privacyNeeds final legal review before launch
Privacy
Torna should collect the minimum data needed to authenticate users, operate sessions, settle money, prevent abuse, and debug reliability.
Data Torna needs
- Login identity such as email, Telegram id when enabled, and account session tokens.
- Wallet, top-up, cardholder confirmation, withdrawal, and audit records.
- Connection metadata needed for routing, billing, abuse prevention, and reliability.
- Supplier server metadata, verification results, probe history, and payout details.
What Torna should not inspect
The network should not inspect browsing payload content. Operators still need enough metadata to issue a route, measure capacity, settle suppliers, prevent abuse, and respond to lawful or safety-critical reports.
Retention
Payment, audit, abuse, and settlement records need longer retention than short-lived session telemetry. Raw troubleshooting data should be minimized and removed when it is no longer operationally useful.
User control
Users should be able to request account export, correction, or deletion. Deletion can exclude records Torna must keep for payment, anti-abuse, tax, legal, or security reasons.